Logo
vulnerabilityCVE-2026-29170
Name
CVE-2026-29170
Source
NVD ( link)Debian ( link)
Description
A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration. Users are recommended to upgrade to version 2.4.68, which fixes this issue.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
apache
Exploitable

Vulnerability Ratings#


6.1
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.4.68
Not Affected
buildroot
master
2.4.68
Not Affected
openwrt
master
2.4.65-r1
Exploitable
yocto
kirkstone
2.4.66
Exploitable
yocto
master
2.4.67
Exploitable
yocto
scarthgap
2.4.67
Exploitable